Methodology overview
Wallet Sleuth turns public blockchain activity into a handful of derived measures: how strongly wallets are related, how risky a wallet or a whole list of wallets looks, whether funds sit close to known bad actors, and how a wallet behaves as a trader. This section explains each of those at the level you need to read a report with confidence. It does not publish the exact weights, thresholds or window sizes, for reasons covered below.
The four families of computation
| Family | What it answers | Where you see it |
|---|---|---|
| Wallet relationships | Which wallets move funds between each other, how strong those ties are, and which wallets probably belong together | Identity graph, Scout canvas, audit discovery and cross-wallet findings |
| Risk score and grade | How much of an audited group's value sits in wallets that carry risk signals, and why | Wallet audit reports, per-wallet risk panels, findings |
| Threat intelligence and taint | Whether a wallet is on a public blocklist, has sent funds to one, or is a short funding hop away from one | Counterparty safety, audit risk factors, wallet detail |
| Behavioral analytics | How a wallet handles a specific token: does it accumulate, dump, ladder out, or move funds off-market | Wallet detail Analytics tab, audit behavior mix |
A fifth page, Data sources, lists every external dataset these computations draw on.
Principles that hold everywhere
Every number is evidence with a source and a date. A risk label names the list it came from and links to the evidence. A finding names the wallets behind it. A relationship is backed by the transfers that formed it. Nothing is a verdict on its own.
Unknown is not clean. When a check could not run, the result is reported as unknown or limited coverage, never as a pass. A wallet on a chain with fewer blocklist sources is marked as having limited coverage rather than being called clear.
Skip rather than guess. Where a source is ambiguous, for example a research write-up that lists both the victim and the attacker, Wallet Sleuth only uses entries whose role is explicit. Anything it cannot place is left out.
Humans confirm identity. Algorithms suggest that wallets belong together. A cluster only becomes strong when a person confirms it, and human confirmation carries more weight than any structural signal.
Descriptive signals never move a grade. Information such as "this wallet is a multisig" or "this token's mint authority is still active" is shown alongside the risk analysis, but the grade is computed only from wallet-level risk factors.
Why exact thresholds are not published
Several detectors look for coordination: buys landing within a short window of each other, near-identical trade sizes, a funding source shared by several wallets. Publishing the precise window or ratio would tell a coordinated group exactly how far apart to space their activity. The pages here describe every signal and the shape of every formula, so you can understand what a result means and challenge it, while the tuned constants stay private and are revisited as behaviour on-chain changes.
Coverage and honesty about limits
Reports state how much of each wallet's history was read, whether a chain's blocklist coverage is partial, and whether a check ran at all. Prices are looked up from multiple providers with fallbacks, and value that cannot be realistically sold is separated from value on paper. When you see a coverage note on a report, it is telling you where the analysis stopped, not hiding a gap.